Apple Ships Emergency Patches for WebKit Flaws Discovered by AI — Cites AI-Driven Exploit Acceleration as Reason for Rushed Timeline
Summary Apple has released out-of-band security updates for iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2, patching nearly 30 vulnerabilities — including four WebKit flaws that were discovered…
Progress Kemp LoadMaster Critical Pre-Auth RCE (CVE-2026-8037) Now Under Active Exploitation
Summary A critical pre-authentication remote code execution vulnerability in Progress Kemp LoadMaster appliances (CVE-2026-8037, CVSS 9.8) is being actively exploited following the public release of proof-of-concept exploit code. The flaw…
CISA Flags SharePoint RCE (CVE-2026-45659) as Actively Exploited — Federal Agencies Given Until July 4 to Patch
Summary CISA has added a high-severity Microsoft SharePoint Server vulnerability (CVE-2026-45659) to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The deserialization-of-untrusted-data flaw carries a CVSS…
Skyhawk Security AI Red Team Takes Over Full AWS Organization in Seconds — Using Only Legitimate Permissions
Skyhawk Security has published research demonstrating that its agentic AI red team system achieved full administrative control of a financial services company’s entire AWS organization in a matter of seconds…
Anthropic Launches Claude Sonnet 5 as US Lifts Export Ban on Fable 5 and Mythos 5 AI Models
Anthropic closed out June with a one-two punch: the launch of Claude Sonnet 5 on June 30 and the simultaneous lifting of U.S. export restrictions on its most powerful models,…
Nissan Employee Data Breached via Oracle PeopleSoft Zero-Day — ShinyHunters Campaign Hits Hundreds of Organizations
Nissan has confirmed a data breach affecting current and former employees across the U.S., Canada, Mexico, and Brazil after attackers exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft, the enterprise…
Microsoft Warns Poisoned MCP Tool Descriptions Can Silently Hijack AI Agents for Data Exfiltration
Microsoft Incident Response and its Defender security research team have published a detailed advisory warning that attackers can hijack AI agents — including those integrated with Microsoft 365 Copilot, Copilot…
macOS XPC Flaw (CVE-2026-39118) Lets Standard Users Silently Kill CrowdStrike, Kandji, and Other Enterprise Security Agents
Security researchers at XM Cyber have publicly disclosed CVE-2026-39118, a macOS vulnerability that allows a standard (non-root) user to silently disable Endpoint Detection and Response (EDR) and Mobile Device Management…
Aflac Japan Breach Exposes 4.38 Million Customers — Sensitive Financial and Personal Data Exfiltrated Over 10-Day Window
Insurance giant Aflac has disclosed a major data breach impacting approximately 4.38 million customers and agents of its Japanese subsidiary. The intrusion, which ran undetected between June 15 and June…
EvilTokens — AI-Powered Phishing-as-a-Service Operation Drives 1,380% Surge in Microsoft 365 Device-Code Phishing
Summary Researchers have detailed “EvilTokens,” a sophisticated AI-powered phishing-as-a-service (PhaaS) operation that abuses Microsoft’s legitimate OAuth 2.0 device-code authentication flow to steal Microsoft 365 tokens at industrial scale. The operation…
